<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ip redirect with PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ip-redirect-with-pix/m-p/306719#M562702</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, That's what I did to fix it but was just curious if I was missing anything in the FW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 Aug 2004 18:31:45 GMT</pubDate>
    <dc:creator>jrhofman</dc:creator>
    <dc:date>2004-08-31T18:31:45Z</dc:date>
    <item>
      <title>ip redirect with PIX</title>
      <link>https://community.cisco.com/t5/network-security/ip-redirect-with-pix/m-p/306717#M562700</link>
      <description>&lt;P&gt;anyone know if you can have a pix do an IP redirect to a host.  I had a situation where hosts have a default to the pix on an inside interface and then the pix had a route to the destination via a router on the same inside interface. This breaks down the 3 way handshake since the SYN Ack from the destination never gets sent back throughthe PIX. It just goes directly to the source host on the same subnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:36:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-redirect-with-pix/m-p/306717#M562700</guid>
      <dc:creator>jrhofman</dc:creator>
      <dc:date>2020-02-21T07:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: ip redirect with PIX</title>
      <link>https://community.cisco.com/t5/network-security/ip-redirect-with-pix/m-p/306718#M562701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope.  The PIX will not work in this design as you want it to.  In order for the PIX to pass packets, the ingress and egress interfaces must be different interfaces.  In other words, it must be received on one interface and be placed on the send buffer of another interface in order to pass.  This behavior is expected and is part of the Adaptive Security Algorithm (ASA) on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your only real option in this case is to change the DG to the router on the inside segment and add a default route on the router pointing back to the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Aug 2004 15:06:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-redirect-with-pix/m-p/306718#M562701</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2004-08-31T15:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: ip redirect with PIX</title>
      <link>https://community.cisco.com/t5/network-security/ip-redirect-with-pix/m-p/306719#M562702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, That's what I did to fix it but was just curious if I was missing anything in the FW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Aug 2004 18:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-redirect-with-pix/m-p/306719#M562702</guid>
      <dc:creator>jrhofman</dc:creator>
      <dc:date>2004-08-31T18:31:45Z</dc:date>
    </item>
  </channel>
</rss>

